1 Setting Up F-PROT Professional 


F-PROT Professional for Windows is primarily a multi-user application and needs an 
administrator to keep it functioning smoothly. F-PROT Professional is automated to 
a great extent, but some jobs, such as updating and modifying, need human 
intervention. 


There is more to being the F-PROT Professional administrator than just 
maintenance. You can determine how the program actually functions and how 
F-PROT Professional appears when installed on the user workstations. 


First you must decide, whether to do a complete or a remote installation to the 
workstations. Complete installation means that F-PROT Professional is installed 
locally to all workstations. Remote installation means that only one installed copy 
of F-PROT Professional exists on the network drive, and all the workstations run the 
same copy. 


First, install F-PROT Professional on your own workstation. Then, customize F-PROT 
Professional to the needs of your organization, before making the program 
available to the users. The steps involved in setting up F-PROT Professional for your 
organization are: 


1. Install the program using your own workstation. 


If your computer is connected to the network, the installation will also create the 
shared communication directory structures on the server disk. For more 
information about installation, refer to Section 9.1, “Installing F-PROT Professional.” 


2. Create the task base. 


Add, modify, schedule, and remove tasks on F-PROT Professional task list to create 
the task base suitable for your organization. For more information, refer to Section 
9.2, “Creating the Task Base.” 


3. Modify the toolbar. 


Add, modify, and remove the buttons on the toolbar. The toolbar should 
correspond to the task base and to the specific needs arising from your system. For 
more information, refer to Section 9.3, “Modifying the Tool Bar.” 


4. Modify the Preferences. 
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Edit the F-PROT Professional Preferences, so that they are suitable for the users. 
Hide at least the Network, Administration, Scanning and Restrictions 
Preferences in the Preferences dialog box. For more information, refer to Section 
9.4, “Editing the Preferences.” 


5. Create the installation directory. 


If you choose to perform the complete installation on workstations, use the 
Distribute F-PROT Installations option in the F-PROT Administration menu to 
create the suitable installation directory. For more information, refer to Section 9.5, 
“Distributing F-PROT Installations.” 


In order to customize F-PROT Professional differently for different user groups, repeat 
steps 2 through 6 for each customization. 


The System Architecture 


There are three basic ways in which the F-PROT Professional system can be set up 
in your organization: 


e with a network, complete installation: F-PROT Professional or F-PROT 
Gatekeeper installed on every workstation; 


e with a network, remote installation: F-PROT Professional or F-PROT 
Gatekeeper installed to run on the server; 


e without a network. 
1 Network: Complete Installation 


There are two options for installing F-PROT Professional for Windows and F-PROT 
Gatekeeper to the network workstations. The preferable method is to install both 
programs on every workstation. The server will act as the communications relay. 
Under such configuration, all the network functions and communications 
capabilities are available. Only the directories needed for communication over the 
network are created on the server. F-PROT Professional tasks and updates are 
distributed automatically to every workstation connected to the network. Refer to 
Chapters 11 and 12 for descriptions of F-PROT Professional for Windows directories 
and files, and their uses. 
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2 Network: Remote Installation 


In some situations, for example, when workstations have insufficient hard disk 
space, it may be necessary to install F-PROT Professional for Windows and F-PROT 
Gatekeeper to run on the server. In this case, the users run the copy of the 
program stored in the server on their own workstations. Only the files and 
directories necessary for communicating through the network are installed on 
individual workstations. Communication to and from individual workstations works 
as well as in the previous option, but the programs cannot be used if the network 
connection breaks down. 


3 No Network Available 


If there is no network available, F-PROT Professional for Windows and F-PROT 
Gatekeeper are installed separately on each workstation. In this case, the 
communications system cannot be used, and each user is individually responsible 
for reporting possible infections to administrator. New versions of the programs 
must be distributed on diskettes. 


Communication and System Management 


Before installing F-PROT Professional for Windows and F-PROT Gatekeeper on a 
network, you should understand how the programs communicate and what kinds of 
communication are supported. 


F-PROT Professional for Windows is not dependent on some specific brands of 
network software. Its communications system works as long as all the workstations 
on the network can treat a part of the server’s hard disk as a shared logical disk. 
Practically, all PC network systems support this, including Banyan Vines, IBM 
AS/400 PC Support, LAN Manager, LANtastic, Novell NetWare, Pathworks, PC LAN, 
PC-NFC and PC/TCP. 


1 Supported Kinds of Communication 


Kinds of CUser Messages and Administrator Bulletins 


F-PROT Professional for Windows is designed to support communication between 
users and administrator. Such communication facilitates efficient administration 


and management of the F-PROT Professional for Windows system. Communication 
between individual users is not supported. Direct information exchange between 
users and administrator takes place in the form of messages and bulletins. 
Messages are notes that users send to administrator. Bulletins are general 
announcements that you can send to all users at once. 


Pre-Configured Tasks 


With F-PROT Professional for Windows you can send pre-configured tasks to user 
workstations through the network. Use this feature to develop uniform scanning 
practices for the whole organization and to target specific threats, such as new 
viruses. When the distributed tasks are no longer needed, they can be removed 
from the system simultaneously. 


The results of tasks’ execution can be set to be sent from user workstations to your 
own, along with any infected files found by F-PROT Professional. 


Updates 


F-PROT Professional for Windows supports automatic updating over the network. 
Whenever you install a new version to the installation directory, the program can 
be automatically updated on all the workstations connected to the network. 


2 The Communication Method 


When F-PROT Professional is installed, the communication structures are created in 
a directory on a shared disk. When you send, for example, an update to users, it is 
copied to the shared drive. F-PROT Professional programs on user workstation then 
copy the new files from the communication directory to the appropriate directories 
on local hard disks. 


Likewise, when F-PROT Professional on a user workstation sends files to the shared 
directory, your program will copy them to the appropriate local F-PROT Professional 
directories. 


3 Access Rights 


The communication directory and its subdirectories are created during F-PROT 
Professional for Windows installation on a shared drive. 


As administrator, you need both read and write access rights to the communication 
directory and all its subdirectories. User access to these directories can be limited 
in order to prevent accidental corruption of the communications system. Suggested 
access rights are listed in the following table. 


Directory Suggested Access Rights 
Communication Directory Read and Write access rights 
BULLETIN Read access rights 

INFECT Write access rights 
MESSAGES Write access rights 

REPORTS Write access rights 

SUSPECT Write access rights 

TASK Read access rights 

UPDATE Read access rights 


UPDATE\WIN95_UP 
UPDATE\WINNT_UP 
UPDATE\OS2_UP 


Read access rights 
Read access rights 


Read access rights 


Access rights policies are necessarily different in different networks. Here, “write 
access” means that any user can create new files and delete files created by any 
user. 


For the communications system to function, users must have both read and write 
access rights to the communication directory. This directory contains the file 
COMM.INF, which keeps track of all the files transferred over the network. 


Refer to the Chapter 11, “Files and Directories,” for more information. 
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Installing F-PROT Professional For Windows 


First install F-PROT Professional for Windows on your own workstation in the 
Network Administration configuration. After completing installation, customize 
F-PROT Professional for Windows for the needs of your organization. When the 
program is ready for distribution, set up AUTOINST installation directory and 
configuration file to have F-PROT Professional installed to workstations centrally. 
Alternatively, prepare the SETUP installation directory and run SETUP from every 
workstation. For more information on distributing the customized program, refer to 
Section 1.7. “Distributing F-PROT Professional Installations.” 


Run the Setup program from the installation diskette as described in the User’s 
Guide. Click Network Administration Installation. 


Choose the directory into which F-PROT Professional for Windows will be installed. 
The default directories are F-PROTW, F-PROT95, or F-PROTNT. If workstations do not 
have sufficient disk space, install F-PROT Professional for Windows into a server 
directory. 


Establish a shared communication directory for all F-PROT Professional users. The 
communication directory locates on a shared disk, so that all F-PROT users have 
full read and write access rights to it. If you are installing the program directly onto 
the server, do not use the F-PROT root directory as the communications directory. 


Type in the administration password and leave the check boxes Enable F-PROT 
Gatekeeper at Windows Start-Up and Load F-Agent at Windows Start-Up 
selected. We recommend that you keep F-Agent active at all times; it runs the 
scheduled tasks and notifies you of messages received from the other 
workstations. 


Click Start Installation. You can quit installation by choosing Exit. Clicking Cancel returns 
you to the previous screen. 
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When the installation is otherwise complete, the program will ask your name, the name of 
your organization, and your workstation’s ID. After you have entered the information and 
clicked OK, installation will be completed. Under Windows 3.1, the dialog box will be 
displayed, asking whether you wish to have Windows restarted in order to have the F-PROT 
Gatekeeper device driver loaded. Click either the Restart Windows Now, or Don’t 
Restart Now. 


The F-PROT Professional program folder will be created, with icons for F-PROT 
Professional, F-Agent, and the ready-made tasks. If you chose to have F-Agent 
loaded at Windows start-up, Setup will add its icon to the Start-Up folder. 


Creating The Task Base 


Create the F-PROT Professional for Windows task base by modifying the task list of 
your own F-PROT Professional program. The tasks can be added, modified, 
scheduled, and removed as described in the User’s Guide. 


Consider the needs of your organization and check the User’s Guide for the 
appropriate options. Decide which types of tasks are required and whether they 
should be scheduled or run interactively.. 


Users can edit or delete tasks, unless you protect the task base from modifications 
by setting appropriate restrictions in Preferences. You can also disable 
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modifications to tasks when using the Distribute Selected Task command from 
the Administration menu. Refer to Section 10.2, “Distributing Tasks through the 
Network,” for further details. 


Modifying The Toolbar 


The toolbar buttons should correspond to the task base you created, as well as to 
the specific needs of your organization. Ideally, the users only need the toolbar to 
manage their own copies of F-PROT Professional for Windows. While this is not 

always possible, the most often needed functions should be linked to the toolbar. 


Instructions on how to create, modify and delete buttons on the toolbar can be 
found in the User’s Guide, Section 6.12, “Creating and Editing Buttons.” 


Editing The Preferences 


Before distributing the program to users, customize the F-PROT Professional 
Preferences. Instructions on how different Preferences affect the program and how 
they can be modified can be found in the User’s Guide, Section 6.3, “Setting Up 
Preferences.” 


However, there are four Preferences not mentioned in the User’s Guide: Network, 
Administration, Restrictions, and Updating. 


1 The Network Preference 


The Network Preference contains the Inform Administrator with Results and 
Send Infected files to Administrator check boxes. Check the boxes to have 
F-PROT Professional send you the task results and copies of infected files from local 
workstations. Whenever F-PROT Gatekeeper finds a virus, it will send a 
corresponding message to administrator. These messages can then be read by 
choosing View User Messages from the Administration menu. 


This dialog box also specifies the name and location of the shared communication 
directory. Select the Notify at Startup if Invalid check box to have F-PROT notify 
you at start-up if the specified directory has become invalid. This Preference also 
allows changes to the F-Agent polling frequency. 


2 The Administration Preference 


In the Administration Preference dialog box, there are three general settings: 


Enable Network Usage. If this check box is not selected, all network related 
functions will be disabled. 


Ask Workstation Prefs on First Startup. If this check box is selected, F-PROT 
Professional for Windows asks for the workstation ID and user name the first time it 
is started on a workstation. F-PROT will not proceed until this information is 
provided. 


Administration Workstation. This option is used to determine whether or not the 
current workstation is the administration workstation. 


You can hide some of the Preferences from the users. If a Preference is hidden, the 
users cannot edit it, and the choices, you have made, stay in effect. It is 
recommended that you hide at least Network, Administration, Restrictions, 
and Updating Preferences. 


The Administration Preference can also be used to change the administration 
password. The user or administrator must know the current password in order to 
change it. 


3 The Restrictions Preference 


Use the Restrictions Preference to restrict the use of F-PROT Professional in the 
user mode. You can prevent users from seeing the program main window by 
selecting the No Main Window check box. In this case, the users can still start 
scans from the program's desktop icon. The other possible restrictions are: Disable 
Creation and Modification of Tasks, and Disable Network Scans. 


4 The Updating Preference 


In the Updating Preference select one of the alternatives for executing F-PROT 
Professional for Windows updates on the workstations: Update Automatically or 
Prompt at Start-Up. 
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Distributing F-PROT Installations 


1 Installation from AUTOINST Directory 


To use the AUTOINST program, the administrator must modify the network login 
batch script (for instance, LOGIN.BAT) of each workstation to invoke AUTOINST 
every time the station logs on to the network. AUTOINST then automatically 
performs the installation or updating of F-PROT, according to the instructions it 
finds in its parameter file AUTOINST.INI. The latter is located on the server, in the 
AUTOINST directory. AUTOINST Wizard creates the AUTOINST directory and makes 
the required entries to the AUTOINST.INI file. Refer to Chapter XX, “AUTOINST,” for 
information on fine-tuning AUTOINST.INI file using text editor and for more 
information about the AUTOINST program. 


To distribute installations using AUTOINST, first perform the Network Administration 
installation on your own workstation. Then do the desired modifications to the 
F-PROT Preferences, toolbar, and the task base. Then choose Distribute F-PROT 


Installations from the Administration menu, and select By Creating 
Installation Directory for AUTOINST. AUTOINST Wizard will start. 


AUTOINST Wizard 


AUTOINST Wizard creates the shared AUTOINST installation directory, and copies 
there all the F-PROT files required for installation, along with the AUTOINST 
program and its parameter file AUTOINST.INI. 


You can move freely back and forth within AUTOINST Wizard by clicking Back and 
Next. You can exit the wizard at any time by clicking Cancel. 


1). Read the information in the first dialog box of AUTOINST and click Next. 


2). Enter the name and location of the AUTOINST directory, which should be 
accessible from all workstations. If the specified directory does not exist, the wizard 
will create it, prompting for your confirmation first. Enter the directory and click 
Next. 


3). In the next dialog box, select the check boxes corresponding to the programs 
you wish to distribute. The available choices are F-PROT Professional and 
F-PROT Gatekeeper. Select the Yes check box to have the networking 
functionality enabled, if you plan to distribute scanning tasks, bulletins, and 


updates, and receive mail from workstations. Click Next. If you selected not to 
enable networking functionality, go to step 5), otherwise, move to the following 


step. 


4). Choose the type of installation AUTOINST should perform. The options are: 
Local Installation or Remote Installation. Choose Remote Installation if you 
wish F-PROT Professional or F-PROT Gatekeeper to run on the server. In this case, 
only the data files, such as reports, configuration files, and others, will be copied to 
the local workstations’ hard disks. If you choose Local Installation, AUTOINST will 
perform the complete installation on the local workstations. Make your choice and 
click Next to move to the next dialog. 


5). Now type in the name of the destination directory on the local workstations’ 
hard disks where the files will be installed. If the specified directory does not exist 
on some of the workstations, AUTOINST will create it. Type in the directory and 
click Next. If you are installing the programs without networking functionality, go 
to step 12), otherwise move to the following step. 


AUTOINST Wizard Lx] 


Choose the source, fram where AUTOINST should obtain 
user and workstation names: 


@ Environment variables 
© Initialization files 


C Windows registry 


Itis important to set them properly in order to be able to 
identify the workstations with virus infections. 


J Cancel 


6). Select the source from which AUTOINST will obtain the user name and the 
workstation ID, both of which will serve to identify the origin of mail received from 
workstations. Select one of the following options: Environment variables, 
Initialization files, Windows registry. Depending on your choice, different 
dialog boxes will be displayed upon clicking Next. If you chose Environment 
variables, go to step 7), if you chose Initialization files, go to step 8), if you 
chose Windows registry, go to step 10). 


7). If you selected environment variables as the source from which AUTOINST will 
obtain user name and workstation name, type in the names of the both 
environment variables in the provided boxes, enclosing each variable between the 
% characters. Click Next to move to step 11). 


8). If you chose initialization files as the source of user and workstation names, add 
the entries that specify the user name to the provided list. If you list multiple 

entries, the first of them that yields result will be used. To add entries, click Add. In 
the displayed dialog box, type in the File name, the Section name, and the Entry 


name and click OK. The new entry will appear on the list. To edit the entry, select 
it on the list and click Modify. Edit the entries in the displayed dialog box. To 
delete an entry, select it on the list, and click Remove. Clicking Clear All will 
delete all the entries. Click Next and move to the step 9). 


9). This dialog is exactly the same as the previous one, except that it prompts to 
add the entries for the workstation name. Add the entries, following the same 
procedure, and click Next to move to step 12). 


10). If you chose Windows registry in step 6), add the registry locator for the user 
name by clicking Add. You can list multiple entries; in this case the first one 
pointing to the valid value will be used. In the Add registry locator dialog box, 
enter the Main key, the Sub key and the Value name. The Main key can be 
selected from the list; the available options are: HKEY_ CLASSES ROOT, 

HKEY CURRENT USER, HKEY_ LOCAL MACHINE, HKEY_USERS. Click OK to return to 
the previous screen. The new entry will appear on the list. To modify an entry, 
select it on the list and click Modify. Then edit the entries in the Modify registry 
locator dialog box. To delete an entry, select it on the list and click Remove. 
Selecting Clear All will delete all the entries. Click Next to move to step 11). 


11). This dialog is exactly the same as the previous one, except that it prompts for 
the registry locator for the workstation name. Add the required entry to the list by 

following the procedure described in the previous step. Click Next to move to the 

next step. 


12). Now the AUTOINST Wizard is ready to copy the files. Click Next and it will start 
copying the files to the installation directory. You will be able to see the progress 
on the screen. When installation is complete, the next dialog box will be displayed. 


13). Click Yes to customize F-PROT Preferences or the settings of F-PROT 
Gatekeeper before distributing the programs to the users. Otherwise, click No. 
Click Finish. 


14). If you have answered Yes in the previous dialog, the Preferences dialog box 
will be displayed. Edit the Preferences as described in Section X.4, “Editing the 


Preferences.” 


15). The final message box will inform you that the AUTOINST installation directory 
has been created and will give the name of the AUTOINST command file, located in 
the AUTOINST directory. Insert this command into the workstations’ login scripts, so 
that it is executed at log-on. The wizard also created AUTOINST.INI file, which can 
be further edited with a text editor to fine-tune its parameters. Refer to Chapter 13, 
“AUTOINST,” for more information on using AUTOINST and fine-tuning 
AUTOINST.INI. 


2 Installation From SETUP Directory 


Another option to distribute F-PROT installations to creating and use the shared 
SETUP installation directory. 


Perform the following steps to create the shared SETUP installation directory: 


1. Perform the Network Administration installation of F-PROT Professional for 
Windows on your own workstation. 


2. Make the desired modifications to the F-PROT Preferences, toolbar, and the 
task base. 


3. Create the SETUP installation directory on the server. 
4. Copy the contents of the original installation diskettes to the SETUP 
installation directory. 


5. Click Distribute F-PROT Installations from the Administration menu, and 
choose By Modifying the Installation Directory. Select the SETUP 
installation directory in the displayed dialog box and click OK. The F-PROT 
configuration and task files will be copied to the SETUP directory. 


Workstation installations can now be done by running the SETUP program on 
workstations from the created SETUP installation directory. 


Updating F-PROT Professional for Windows 


The easiest way to update F-PROT Professional for Windows is via the network. The 
best way to handle updating is first to update your own program, and then use it as 
the source for the update. F-PROT Professional updating function uses the F-PROT 
root directory as the source directory. 


Updating Your Own Program 


The easiest way to update a new version to your own workstation or to the server, 
if F-PROT Professional is installed to run there, is to update it from new installation 
diskettes. Use the Update Installation option. This installation replaces the old 
program files on your hard disk. If the program is installed to run on the server, the 
individual workstations do not hold any files that need to be updated. Make sure 
that there are no active users of F-PROT Professional at the time of updating, 
because the update procedure cannot copy the necessary files, if they are open. 


Sending Updates To Users 


After you installed a new version of F-PROT Professional for Windows on your own 
workstation, send it to the users via network. This can be done by choosing Send 
Update from the Administration menu. The program will copy all the files and 
directories under the F-PROT Professional root directory to the UPDATE directory on 
the shared disk. 


When you send an update to users, all programs installed under the F-PROT 
Professional root directory are copied to the shared disk. If you have programs like 
F-CHECK or F-PROT for DOS installed in their own directories under the root 
directory, they will also be copied to the local workstations. As you can see, this 
feature can be used to update or distribute programs which are unrelated to 
F-PROT Professional for Windows. 


On workstations, F-PROT Professional, when started, checks the UPDATE directory. 
If a new version has become available, F-PROT updates itself. If the UPDATE 
directory contains other programs, F-PROT Professional also copies them to the 


local hard disk. Refer to Section 11, “Files and Directories” for more information on 
how F-PROT Professional update process is executed. 


